Remote Cross Site Scripting Vulnerability in HPE Integrated Lights-Out
CVE-2019-11982
8.3HIGH
Summary
A remote cross site scripting vulnerability has been discovered in HPE Integrated Lights-Out systems. This issue affects iLO 4 versions prior to 2.61b and iLO 5 versions before 1.39, allowing attackers to execute malicious scripts in the context of a user’s session, posing significant risks for session hijacking and unauthorized actions. It is crucial for users to apply security updates to mitigate potential threats and protect their systems.
Affected Version(s)
HPE iLO4 and HPE iLO5 iLO4 prior to v2.61b and iLO5 prior to v1.39
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved